### Fixed - The sweep's `bootstrap` value crosses the `workflow_call` boundary as a declared input passed by the caller — a called workflow cannot read the caller's dispatch inputs on this forge (#215). - Before the bridge, `github.event.inputs` was empty inside the called workflow, so every dispatch-woken sweep bootstrapped: ~20 label upserts on each board event (#215). - The caller maps an empty top-level value to `no` explicitly, so a cron-woken sweep can never bootstrap; the declared input also defaults to `no`, so a consumer that passes nothing gets the safe path (#215). - The gate feeds the declared input to `labels-reconcile` unchanged, so an invalid value meets the action's own `yes|no` refusal instead of being silently coerced (#215). - `docs/CONSUMERS.md`'s published sweep stub carries the same pass-through — without it every consumer inherits the defect ceremony fixed for itself (#215). ### Added - `test/labels-bootstrap.test.sh` pins the bridge at every hop: the declared boundary, both gate sites as the identity, no expression reading `github.event.inputs`, the caller and stub pass-throughs byte-exact, and the four value paths driven through the shipped expressions into the action's real validator (#215).